- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
hi
Could someone explain why this is happening
I assume you wonder why it is blocked? Maybe this SK helps https://support.checkpoint.com/results/sk/sk126172
Or something else is wrong?
Appears its related to default geo policy. You definitely should be using updatable objects for geo policy starting R80.20 version. I would examine current policy and see how Brazil is configured.
Andy
When I do the application with the updated objects it gives the same error shown above, I believe it is something in the base of the checkpoint that inserted this ips incorrectly
So if you try using geo updata ble objects and I assume you disabled legacy geo policy, you get same error?
Andy
hi @the_rock
I didn't disable the default policy of GEO, I created a rule on the layer network with the update objets. Even so, the error happened, the access to the Brazilian continent was blocked
Right, but whole point of using updatable objects for countries is to disable legacy geo policy.
Andy
Hi @the_rock
Even applying the rule does not work with the update objects. I believe that the problem is at the base?
K, just to make sure we are on the same page here..are you trying to block/allow given country or specific IP from that country or what exactly?
Andy
The legacy Geo Policy is enforced well before Geo Updatable Objects, at roughly the same time as antispoofing enforcement. So if traffic is dropped by the legacy Geo Policy it will be dropped regardless of how your main policy layers are configured with Geo Updatable Objects. To disable the legacy Geo Policy:
1) Under Shared Policies...Geo Policy...select Policy
2) Make sure "Default Geo Policy" is selected in the dropdown at the top of the screen
3) Select Inactive or "Monitor Only", your choice
4) Using Geo Updatable objects, ban any countries you want using Geo Updatable Objects in the first layer of your policy package
5) Publish and install policy.
I guess I thought I mentioned to disable it previously, but my bad, I did not. @lluner , thats what you have to do first.
Andy
I assume you wonder why it is blocked? Maybe this SK helps https://support.checkpoint.com/results/sk/sk126172
Or something else is wrong?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 18 | |
| 15 | |
| 13 | |
| 12 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY